⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
Cisco disclosed active exploitation of CVE-2026-76460, a CVSS 10.0 authentication-bypass flaw in Identity Services Engine (ISE) that can give remote unauthenticated attackers access to affected devices. The weekly roundup also covers Plugin4Shell, a SHA-pinning bypass enabling zero-click RCE in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI, alongside CVE-2026-32882 in Discourse community forum, fixed upstream in libheif 1.22.0. Other incidents include ClickFix campaigns, Brevo's supply-chain compromise, and KREMLIN malware targeting Google Chrome and Microsoft Edge credentials.